← Back to CVE search

CVE-2026-62641

Roundcube Webmail

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

CVSS 4.3EPSS 0.252%Risk 0.44
View source
Published
2026-07-14 16:17:04
Affected versions
<1.6.17, <1.7.2
Type
Web application
Last modified
2026-07-20 12:56:55
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L